<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Funsec</title>
    <link>http://seclists.org/#funsec</link>
    <atom:link href="http://seclists.org/rss/funsec.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>While most security lists ban off-topic discussion, Funsec is a haven for free community discussion and enjoyment of the lighter, more humorous side of the security community</description>
    <pubDate>Tue, 22 May 2012 21:30:02 GMT</pubDate>
    <lastBuildDate>Tue, 22 May 2012 21:30:02 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>malicious binaries</title>
    <link>http://seclists.org/funsec/2012/q2/64</link>
    <description>&lt;p&gt;Posted by Daniel Otis on May 22&lt;/p&gt;Many moons ago I ran a site to share malware binaries amongst the people &lt;br&gt;
on this list.  I&amp;apos;m always looking for a new source of data so I am &lt;br&gt;
wondering if there is a current free source for sharing malicious &lt;br&gt;
binaries for analysis.  Thanks!  Also, I wouldn&amp;apos;t mind running such a &lt;br&gt;
service again, the only problem was I was the only one sharing ;)&lt;br&gt;
&lt;br&gt;
Daniel&lt;br&gt;</description>
    <pubDate>Tue, 22 May 2012 21:24:02 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/64</guid>
  </item>
  <item>
    <title>Re: Rotten AV proves &quot;free market&quot; false?</title>
    <link>http://seclists.org/funsec/2012/q2/63</link>
    <description>&lt;p&gt;Posted by Drsolly on May 22&lt;/p&gt;&amp;quot;So why are the outcomes of this market so poor? &amp;quot;&lt;br&gt;
&lt;br&gt;
Because the job that they&amp;apos;re trying to do, can&amp;apos;t actually be done.&lt;br&gt;</description>
    <pubDate>Tue, 22 May 2012 11:49:14 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/63</guid>
  </item>


  <item>
    <title>Rotten AV proves &quot;free market&quot; false?</title>
    <link>http://seclists.org/funsec/2012/q2/62</link>
    <description>&lt;p&gt;Posted by Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah on May 21&lt;/p&gt;(Or lousy OS situation, or pitiful software security in general ...)&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.businessinsider.com/when-competition-easy-entry-and-no-government-&quot;&gt;http://www.businessinsider.com/when-competition-easy-entry-and-no-government-&lt;/a&gt;&lt;br&gt;
produces-lousy-results-a-quick-look-at-the-anti-virus-and-anti-malware-market-&lt;br&gt;
2012-5&lt;br&gt;
&lt;br&gt;
or&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://is.gd/yfQXMG&quot;&gt;http://is.gd/yfQXMG&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
(I do recall some research that indicates &amp;quot;low cost of entry&amp;quot; actually promotes &lt;br&gt;
monoculture ...)&lt;br&gt;
&lt;br&gt;
======================  (quote inserted randomly by Pegasus Mailer)&lt;br&gt;
rslade () vcn...&lt;br&gt;</description>
    <pubDate>Mon, 21 May 2012 19:33:39 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/62</guid>
  </item>


  <item>
    <title>(Redundant) Backup is good</title>
    <link>http://seclists.org/funsec/2012/q2/61</link>
    <description>&lt;p&gt;Posted by Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah on May 15&lt;/p&gt;An example:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.youtube.com/watch?v=EL_g0tyaIeE&quot;&gt;http://www.youtube.com/watch?v=EL_g0tyaIeE&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
======================  (quote inserted randomly by Pegasus Mailer)&lt;br&gt;
rslade () vcn bc ca     slade () victoria tc ca     rslade () computercrime org&lt;br&gt;
         The client interface is the boundary of trustworthiness.&lt;br&gt;
                                             - Tony Buckland, UBC&lt;br&gt;
victoria.tc.ca/techrev/rms.htm &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.infosecbc.org/links&quot;&gt;http://www.infosecbc.org/links&lt;/a&gt;...&lt;br&gt;</description>
    <pubDate>Tue, 15 May 2012 23:17:58 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/61</guid>
  </item>
  <item>
    <title>Nigerian funds transfer safe</title>
    <link>http://seclists.org/funsec/2012/q2/60</link>
    <description>&lt;p&gt;Posted by Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah on May 15&lt;/p&gt;I&amp;apos;ve always been a bit worried that those offers I&amp;apos;ve gotten from Nigerian &lt;br&gt;
individuals and banks might be &amp;quot;too good to be true.&amp;quot;  So it&amp;apos;s really nice that the &lt;br&gt;
FBI has taken time from it&amp;apos;s busy schedule to assure me, even before I asked, that &lt;br&gt;
the sca... I mean, deal, is safe.&lt;br&gt;
&lt;br&gt;
(Now all I have to worry about is that the FBI is eeking to wiretap the whole &lt;br&gt;
Internet.  Must be an expensive proposition.  Maybe they are...&lt;br&gt;</description>
    <pubDate>Tue, 15 May 2012 22:12:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/60</guid>
  </item>


  <item>
    <title>Error in Finnish e-prescription software randomly added characters when Return was used</title>
    <link>http://seclists.org/funsec/2012/q2/59</link>
    <description>&lt;p&gt;Posted by Juha-Matti Laurio on May 13&lt;/p&gt;Finnish Medical Journal (in Finnish):&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.laakarilehti.fi/uutinen.html?opcode=show/news_id=12029/type=1&quot;&gt;http://www.laakarilehti.fi/uutinen.html?opcode=show/news_id=12029/type=1&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Google translation:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://translate.google.com/translate?hl=en?sl=fi&amp;amp;tl=en&amp;amp;u=http%3A//www.laakarilehti.fi/uutinen.html%3Fopcode%3Dshow/news_id%3D12029/type%3D1&quot;&gt;http://translate.google.com/translate?hl=en?sl=fi&amp;amp;tl=en&amp;amp;u=http%3A//www.laakarilehti.fi/uutinen.html%3Fopcode%3Dshow/news_id%3D12029/type%3D1&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
It is reported that using Return key in Effica e-prescription software randomly caused the program to add or destroy &lt;br&gt;
characters typed by the doctor.&lt;br&gt;
According to the...&lt;br&gt;</description>
    <pubDate>Sun, 13 May 2012 09:58:14 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/59</guid>
  </item>
  <item>
    <title>Re: .secure TLD</title>
    <link>http://seclists.org/funsec/2012/q2/58</link>
    <description>&lt;p&gt;Posted by valdis . kletnieks on May 12&lt;/p&gt;On Fri, 11 May 2012 21:23:01 -0400, Ben April said:&lt;br&gt;
&lt;br&gt;
Read between the lines.  The guy scored $9M in startup funding, and&lt;br&gt;
only has to pay ICANN $185K for the .secure TLD. And then he gets to&lt;br&gt;
collect *more* money from anybody silly enough to buy into the TLD.&lt;br&gt;
&lt;br&gt;
Step 3: Profit!&lt;br&gt;</description>
    <pubDate>Sun, 13 May 2012 04:54:17 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/58</guid>
  </item>


  <item>
    <title>PCI DSS and BEAST</title>
    <link>http://seclists.org/funsec/2012/q2/57</link>
    <description>&lt;p&gt;Posted by Drsolly on May 12&lt;/p&gt;I just spent two effortful days getting my Secure Server to pass the PCI&lt;br&gt;
DSS. The big problem is the BEAST vulnerability. And it&amp;apos;s a corker. What&lt;br&gt;
you have to do to get your certification, is disable most of the strong&lt;br&gt;
crypto that you accept, and only accept some of the weaker ones (a bit of&lt;br&gt;
research on the web will give you that info).&lt;br&gt;
&lt;br&gt;
Having done that, and gotten my certification renewed, my QA told me that&lt;br&gt;
some of the big banks...&lt;br&gt;</description>
    <pubDate>Sat, 12 May 2012 18:42:32 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/57</guid>
  </item>
  <item>
    <title>Re: .secure TLD</title>
    <link>http://seclists.org/funsec/2012/q2/56</link>
    <description>&lt;p&gt;Posted by Bruce Ediger on May 12&lt;/p&gt;What happened to &amp;quot;The map is not the territory&amp;quot;?&lt;br&gt;
&lt;br&gt;
After that, I want to know what happened to &amp;quot;The tap is not&lt;br&gt;
meritorious&amp;quot;.&lt;br&gt;</description>
    <pubDate>Sat, 12 May 2012 16:54:09 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/56</guid>
  </item>
  <item>
    <title>Re: .secure TLD</title>
    <link>http://seclists.org/funsec/2012/q2/55</link>
    <description>&lt;p&gt;Posted by Nick FitzGerald on May 11&lt;/p&gt;Ben April wrote:&lt;br&gt;
&lt;br&gt;
Well, the whole idea is somewhere between hilarious and blatantly &lt;br&gt;
ignorant on its face, so that&amp;apos;s funny (as in &amp;quot;funny sad&amp;quot; -- these folk &lt;br&gt;
do seem to think they&amp;apos;re doing something useful that will make a &lt;br&gt;
difference) right off the bat...&lt;br&gt;
&lt;br&gt;
If they really want to &amp;quot;assure security&amp;quot; they won&amp;apos;t let any of their &lt;br&gt;
registered domains install any currently-popular web-apps, PHP or, &lt;br&gt;
realistically, even...&lt;br&gt;</description>
    <pubDate>Sat, 12 May 2012 04:30:05 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/55</guid>
  </item>
  <item>
    <title>.secure TLD</title>
    <link>http://seclists.org/funsec/2012/q2/54</link>
    <description>&lt;p&gt;Posted by Ben April on May 11&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.darkreading.com/authentication/167901072/security/security-management/240000187/new-i-secure-i-internet-domain-on-tap.html&quot;&gt;http://www.darkreading.com/authentication/167901072/security/security-management/240000187/new-i-secure-i-internet-domain-on-tap.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
If they really wanted to be secure they would require the&lt;br&gt;
implementation of RFC 3514&lt;br&gt;</description>
    <pubDate>Sat, 12 May 2012 01:47:26 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/54</guid>
  </item>


  <item>
    <title>Terrorist toddlers (Toddler terrorists?)</title>
    <link>http://seclists.org/funsec/2012/q2/53</link>
    <description>&lt;p&gt;Posted by Robert Slade on May 11&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.vancouversun.com/travel/toddler+JetBlue+employees+pull+month+from+flight+over+list/6606185/story.html&quot;&gt;http://www.vancouversun.com/travel/toddler+JetBlue+employees+pull+month+from+flight+over+list/6606185/story.html&lt;/a&gt;&lt;br&gt;</description>
    <pubDate>Fri, 11 May 2012 18:14:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/53</guid>
  </item>


  <item>
    <title>Re: As you were ...</title>
    <link>http://seclists.org/funsec/2012/q2/52</link>
    <description>&lt;p&gt;Posted by Paul Ferguson on May 10&lt;/p&gt;I knew it! :-)&lt;br&gt;
&lt;br&gt;
- ferg&lt;br&gt;
&lt;br&gt;
- Sent from my Android device.&lt;br&gt;</description>
    <pubDate>Thu, 10 May 2012 21:41:59 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/52</guid>
  </item>
  <item>
    <title>As you were ...</title>
    <link>http://seclists.org/funsec/2012/q2/51</link>
    <description>&lt;p&gt;Posted by Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah on May 10&lt;/p&gt;Apparently the Mayan&amp;apos;s were as bad as anyone else changing their minds on the &lt;br&gt;
date of the end of the world ...&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.sciencedaily.com/releases/2012/05/120510141905.htm&quot;&gt;http://www.sciencedaily.com/releases/2012/05/120510141905.htm&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
======================  (quote inserted randomly by Pegasus Mailer)&lt;br&gt;
rslade () vcn bc ca     slade () victoria tc ca     rslade () computercrime org&lt;br&gt;
The evening news is where they begin with &amp;apos;Good evening,&amp;apos; and&lt;br&gt;
then proceed to tell you why it isn&amp;apos;t....&lt;br&gt;</description>
    <pubDate>Thu, 10 May 2012 21:29:04 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/51</guid>
  </item>
  <item>
    <title>7 Ways Oracle Puts Database Customers At Risk</title>
    <link>http://seclists.org/funsec/2012/q2/50</link>
    <description>&lt;p&gt;Posted by Juha-Matti Laurio on May 10&lt;/p&gt;A very good coverage:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.darkreading.com/database-security/167901020/security/news/232901381/7-ways-oracle-puts-database-customers-at-risk.html&quot;&gt;http://www.darkreading.com/database-security/167901020/security/news/232901381/7-ways-oracle-puts-database-customers-at-risk.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Juha-Matti&lt;br&gt;</description>
    <pubDate>Thu, 10 May 2012 15:38:03 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/funsec/2012/q2/50</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>

